CVE-2026-92780
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| didi | KnowStreaming | 0 <= 3.4.1 | affected |
Weaknesses
- CWE-862: Missing Authorization
References
- https://github.com/didi/KnowStreaming/issues/1263
- https://github.com/didi/KnowStreaming
- https://github.com/didi/KnowStreaming/blob/v3.4.0/km-rest/src/main/java/com/xiaojukeji/know/streaming/km/rest/interceptor/PermissionInterceptor.java#L46-L74
- https://www.vulncheck.com/advisories/knowstreaming-through-3.4.1-missing-authorization-on-the-rest-api
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.